To Qualify: You should live in the Richmond, VA area today.
Experience the HCA Healthcare difference where colleagues are trusted, valued members of our healthcare team. Grow your career with an organization committed to delivering respectful, compassionate care, and where the unique and intrinsic worth of each individual is recognized. Submit your application for the opportunity below: Security Engineer
Job Summary and Qualifications
The IPS Field Security Engineer will support Division and Facility Network/System Engineers and Administrators by analyzing a wide range of applications, network configurations, and security architectures to ensure the security, integrity, and regulatory compliance of critical information transmitted or stored within the enterprise. Their role is to facilitate the discovery of information and IT-related risks, apply critical thinking to assumptions and develop the right security position/priorities that: first, attain compliance; second, address the material risks to the company while allowing the business to attain its objectives. This position blends cybersecurity engineering with system infrastructure expertise to support risk management, threat mitigation, infrastructure reliability, and compliance with IT and security standards.
The IPS Field Security Engineer will work across multiple domains of information security (i.e. Security and Risk Management, Asset Security, Security Architecture and Engineering, Network Security, Identity and Access Management, Security Assessment and Testing, and Security Operations), providing consultation, assessments, and security/technical guidance to business units and IT teams.
Major Responsibilities:
Risk Management and Security Consulting
• Serves as an internal information security consultant to the enterprise while balancing the needs of the business.
• Research and recommend solutions that meet security standards while ensuring functionality for business continuity.
• Drive and manage execution of corrective actions to address deficiencies identified during risk assessments.
• Drive targeted security risk reduction within IT
• Augment IT resources by prioritizing, coordinating, and performing security Division and Facility hygiene activities.
• Support implementation & configuration of security controls.
• Translate security standards and regulatory requirements into actionable technical and business requirements.
• Lead and support the IPS program by assessing new applications and technologies and ensuring they are implemented in accordance with company standards
• Partner with appropriate stakeholders on vulnerability remediation
• Engage in Architecture Review Committee discussions to identify and address Third Party solution variance from company standards
• Support, coordinate, and manage incident response and investigation activities
• Evaluate and recommend security solutions that balance risk mitigation with business functionality
• Drive ongoing compliance with IPS policies, standards, and operational procedures
• Serve as an internal security consultant across business units to provide technical security consultation on appropriate controls that balance business and security requirements.
• Provide hands-on support for corporate-driven security efforts
• Manage operational processes that monitor and respond to potential security threats
Security Engineering & Architecture
• Evaluate new and proposed security technologies and assist in their integration
• Identify appropriate security controls as part of the field intake process and ensure security controls are implemented and configured.
• Assist in the design and implementation of secure network, application, and system architectures
• Educate ITG colleagues on security policies and standards to help ensure compliance.
• Partner with IT colleagues to assure ongoing maturity of IT operational security controls.
• Participate in the development and testing of disaster recovery and contingency plans
Security Operations and Threat Management
• Partner with corporate and local departments as required to facilitate rapid response to cybersecurity events and determine appropriate technical mitigations as necessary.
• Maintain awareness of emerging threats, vulnerabilities, and mitigation techniques.
• Coordinate Cyber Defense Center (CDC), MSSP, and Cyber Problem Effort and Resiliency (CPER) response efforts and report on progress
• Augment IT response capabilities by providing hands-on technical support and remediation
• Partner with IPS Facility Security Analyst and DISA to oversee processes for review and approval of security exception requests.
Vendor Systems Security
• Partner with appropriate business and IT leadership to help ensure systems, services, and devices receive appropriate assessments and remediation as part of local on-boarding processes.
• Partner with business and IT leadership to ensure proper controls are in place for existing vendor-maintained solutions.
• Work with vendors to remediate security vulnerabilities in response to security events
• Performs other duties as assigned
• Practices and adheres to the “Code of Conduct” philosophy and “Mission and Value Statement.”
Education & Experience:
• Bachelors degree and 3+ years of experience in a relevant field -Required
• High School Graduate/Equivalent and 3+ years’ experience in related field -Required
• Masters degree -Preferred
• 3+ years of experience in security risk management, information security domains, and/or hospital operations. Preferred
Licenses, Certifications, & Training:
• CISSP, CISA, CISM, CCNA, or other relevant certifications in network administration, information security or cyber risk management -Preferred
> Up to 50% local travel.
Benefits
HCA Healthcare, offers a total rewards package that supports the health, life, career and retirement of our colleagues. The available plans and programs include:
- Comprehensive benefits for medical, prescription drug, dental, vision, behavioral health and telemedicine services
- Wellbeing support, including free counseling and referral services
- Time away from work programs for paid time off, paid family leave, long- and short-term disability coverage and leaves of absence
- Savings and retirement resources, including a 401(k) Plan with a 100% match on 3% to 9% of pay (based on years of service), Employee Stock Purchase Plan, flexible spending accounts, preferred banking partnerships, retirement readiness tools, rollover support and financial wellbeing counseling
- Education support through tuition assistance, student loan assistance, certification support, dependent scholarships and a partnership with Galen College of Nursing
- Additional benefits for fertility and family building, adoption assistance, life insurance, supplemental health protection plans, auto and home insurance, legal counseling, identity theft protection and consumer discounts
Learn more about Employee Benefits
Note: Eligibility for benefits may vary by location.
ITG transforms healthcare and gives people healthier tomorrows. We deliver information technology strategy, support, and solutions. ITG improve and enhance patient care and business operations. We deliver services at administrative locations, data centers, and hospitals. The facilities we support are located in 20+ states and the United Kingdom. Our team works to move healthcare forward. We do this by seeking, embracing, developing, and delivering technology for patient care.
HCA Healthcare has been recognized as one of the Worlds Most Ethical Companies® by the Ethisphere Institute more than ten times. In recent years, HCA Healthcare spent an estimated 3.7 billion in cost for the delivery of charitable care, uninsured discounts, and other uncompensated expenses.
"There is so much good to do in the world and so many different ways to do it."- Dr. Thomas Frist, Sr.
HCA Healthcare Co-Founder
If you find this opportunity compelling, we encourage you to apply for our Security Engineer opening. We promptly review all applications. Highly qualified candidates will be directly contacted by a member of our team. We are interviewing - apply today!
We are an equal opportunity employer. We do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status.